Impact
The vulnerability is a missing authorization flaw that enables attackers to bypass the plugin’s access control mechanisms. This can allow them to view or manipulate data that should be restricted, potentially exposing sensitive information or altering plugin configuration. The weakness is classified as CWE‑862, representing unauthorized access due to improper access control.
Affected Systems
WordPress sites running Deepen Bajracharya’s Video Conferencing with Zoom plugin version 4.6.6 or earlier are affected. Versions before the earliest listed release are also vulnerable.
Risk and Exploitability
The CVSS score of 4.3 indicates a moderate impact, while the EPSS score below 1 % suggests exploitation is currently unlikely. The vulnerability is not present in the CISA Known Exploited Vulnerabilities catalog. Based on the description, the likely attack vector is remote via the web interface provided by the plugin, and an attacker would not require authenticated access to exploit the flaw.
OpenCVE Enrichment